Chapter 6 Traffic Policy

Figure 6.17 Traffic rule — selecting an action

Permit — traffic will be allowed by the firewall

Deny — client will be informed that access to the address or port is denied. The client will be warned promptly, however, it is informed that the traffic is blocked by firewall.

Drop — all packets that fit this rule will be dropped by firewall. The client will not be sent any notification and will consider the action as a network outage. The action is not repeated immediately by the client (the client expects a response and tries to connect later, etc.).

Note: It is recommended to use the Deny option to limit the Internet access for local users and the Drop option to block access from the Internet.

Log

The following actions can be taken to log traffic:

Figure 6.18 Traffic rule — packet/connection logging

102

Page 102
Image 102
Kerio Tech Firewall6 manual Log, 102